]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
netfilter: nf_conntrack: Add allow_clash to generic protocol handler
authorYuto Hamaguchi <Hamaguchi.Yuto@da.MitsubishiElectric.co.jp>
Fri, 19 Dec 2025 11:53:51 +0000 (20:53 +0900)
committerFlorian Westphal <fw@strlen.de>
Tue, 20 Jan 2026 15:23:37 +0000 (16:23 +0100)
commit8a49fc8d8a3e83dc51ec05bcd4007bdea3c56eec
tree843782144d06504fc05178a1d14bcc30c88069ea
parent6f93616a7323d646d18db9c09f147e453b40fdd7
netfilter: nf_conntrack: Add allow_clash to generic protocol handler

The upstream commit, 71d8c47fc653711c41bc3282e5b0e605b3727956
 ("netfilter: conntrack: introduce clash resolution on insertion race"),
sets allow_clash=true in the UDP/UDPLITE protocol handler
but does not set it in the generic protocol handler.

As a result, packets composed of connectionless protocols at each layer,
such as UDP over IP-in-IP, still drop packets due to conflicts during conntrack insertion.

To resolve this, this patch sets allow_clash in the nf_conntrack_l4proto_generic.

Signed-off-by: Yuto Hamaguchi <Hamaguchi.Yuto@da.MitsubishiElectric.co.jp>
Signed-off-by: Florian Westphal <fw@strlen.de>
net/netfilter/nf_conntrack_proto_generic.c